Q: 12
Which of the following will provide the MOST guidance when deciding the level of protection for an
information asset?
Options
Discussion
C vs A for me, but C lines up with risk-focused asset protection. Not totally sure!
C makes the most sense since you need to tie protection levels to what would actually affect the business. IS program is important but protecting assets is always about avoiding hits to core business functions. Pretty sure that's right, anyone see it differently?
A not C. I think the impact on the IS program could set the standard for protection levels in some cases. Trap is confusing business impact with policy guidance.
Maybe A, the impact on information security program. I think some people pick this as a trap since programs set policy for protection levels.
Its C because the business impact tells you exactly how much protection is justified for an asset. Cost and IS program matter, but you always start with how it affects business ops. I think that lines up with risk assessment best practices, agree?
encountered exactly similar question in my exam in my practice tests, pretty sure it’s C.
Why not A? IS program impact seems like it fits here.
Be respectful. No spam.
Question 12 of 35